From: "nagachika (Tomoyuki Chikanaga) via ruby-core" Date: 2023-03-29T06:27:38+00:00 Subject: [ruby-core:113036] [Ruby master Bug#19556] Backport latest versions of URI Issue #19556 has been updated by nagachika (Tomoyuki Chikanaga). Backport changed from 2.7: DONE, 3.0: REQUIRED, 3.1: REQUIRED, 3.2: DONE to 2.7: DONE, 3.0: REQUIRED, 3.1: DONE, 3.2: DONE merged pull request for ruby_3_1 at 66ad6e533e968cb6a8f54674b1c3a3fd0a316893. ---------------------------------------- Bug #19556: Backport latest versions of URI https://bugs.ruby-lang.org/issues/19556#change-102573 * Author: hsbt (Hiroshi SHIBATA) * Status: Closed * Priority: Normal * Backport: 2.7: DONE, 3.0: REQUIRED, 3.1: DONE, 3.2: DONE ---------------------------------------- https://www.ruby-lang.org/en/news/2023/03/28/redos-in-uri-cve-2023-28755/ has been published. We should upgrade URI version each stable branch. * [for Ruby 3.0](https://github.com/ruby/ruby/pull/7607) * [for Ruby 3.1](https://github.com/ruby/ruby/pull/7605) -- https://bugs.ruby-lang.org/ ______________________________________________ ruby-core mailing list -- ruby-core@ml.ruby-lang.org To unsubscribe send an email to ruby-core-leave@ml.ruby-lang.org ruby-core info -- https://ml.ruby-lang.org/mailman3/postorius/lists/ruby-core.ml.ruby-lang.org/